CVE-2002-0257: High severity USANet Creations Makebid Auction Deluxe vulnerability
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0257?
CVE-2002-0257 is considered moderately severe as it allows remote attackers to exploit cross-site scripting vulnerabilities.
How do I fix CVE-2002-0257?
To fix CVE-2002-0257, you should implement input validation and sanitization for user-provided data in the affected form fields.
What software is affected by CVE-2002-0257?
CVE-2002-0257 affects version 3.30 of MakeBid Auction Deluxe and several specific versions of the Apache HTTP Server.
What types of information can be exposed by CVE-2002-0257?
CVE-2002-0257 can expose sensitive user information through various form fields like TITLE, EMAIL, and ADDRESS.
Is CVE-2002-0257 still a concern today?
While CVE-2002-0257 is an older vulnerability, it remains a concern for systems that have not been updated or patched.